An intelligent DDoS attack detection tree-based model using Gini index feature selection method

被引:20
|
作者
Bouke, Mohamed Aly [1 ]
Abdullah, Azizol [1 ]
ALshatebi, Sameer Hamoud [1 ]
Abdullah, Mohd Taufik [1 ]
El Atigh, Hayate [2 ]
机构
[1] Univ Putra Malaysia, Fac Comp Sci & Informat Technol, Serdang 43400, Malaysia
[2] Bandirma Onyedi Eylul Univ, Fac Comp Engn, TR-10200 Balikesir, Turkiye
关键词
Feature importance; Decision trees; Gini index; DDoS; UNSW-NB15; DEEP LEARNING APPROACH; INTERNET; THINGS; PERFORMANCE; SYSTEMS;
D O I
10.1016/j.micpro.2023.104823
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Cyber security has recently garnered enormous attention due to the popularity of the Internet of Things (IoT), intelligent devices' rapid growth, and a vast number of real-life applications. As a result, detecting threats and constructing an efficient Intrusion detection system (IDS) have become crucial in today's security requirements. Withal, the large amount of high dimensional data might influence detection effectiveness and raise the computation requirements. Artificial Intelligence (AI) has recently attracted much attention and is widely used to build intelligent IDSs to preserve data confidentiality, integrity, and availability. Distributed denial of service (DDoS) is a denial of service (DoS) variant mainly targeting asset availability. Preventing DoS at the network or infrastructure level typically depends on implementing an IDS. This paper proposes a novel intelligent DDoS attack detection model based on a Decision Tee (DT) algorithm and an enhanced Gini index feature selection method. Our approach is evaluated on the UNSW-NB15 dataset, which contains 1,140,045 samples and is more recent and comprehensive than those used in previous works. Our system achieved an overall accuracy of 98%, outperforming baseline models that used more advanced algorithms such as Random Forest and XGBoost. Our enhanced Gini index feature selection method allowed us to select only 13 out of 45 security features, signifi-cantly reducing the data dimensionality and avoiding overfitting issues. Our model also has a lower false alarm rate, misclassifying only 2% of the testing instances. Our approach is, therefore, highly effective and efficient, with the potential to be used in real-world network security applications.
引用
收藏
页数:10
相关论文
共 50 条
  • [41] INTELLIGENT TREE-BASED ENSEMBLE APPROACHES FOR PHISHING WEBSITE DETECTION
    Alsariera, Yazan A.
    Balogun, Abdullateef O.
    Adeyemo, Victor E.
    Tarawneh, Omar H.
    Mojeed, Hammed A.
    JOURNAL OF ENGINEERING SCIENCE AND TECHNOLOGY, 2022, 17 (01): : 563 - 582
  • [42] Iterative Feature Selection-Based DDoS attack Prevention Approach in Cloud
    Nalem, Sarah
    Khedr, Ayman E.
    Idrees, Amira M.
    Marie, Mohamed
    INTERNATIONAL JOURNAL OF ELECTRICAL AND COMPUTER ENGINEERING SYSTEMS, 2023, 14 (02) : 197 - 205
  • [43] Tree-based Intelligent Intrusion Detection System in Internet of Vehicles
    Yang, Li
    Moubayed, Abdallah
    Hamieh, Ismail
    Shami, Abdallah
    2019 IEEE GLOBAL COMMUNICATIONS CONFERENCE (GLOBECOM), 2019,
  • [44] Malware Detection Method using Tree-based Machine Learning Algorithms
    Okada, Satoshi
    Matsuda, Wataru
    Fujimoto, Mariko
    Mitsunaga, Takuho
    2021 IEEE INTERNATIONAL CONFERENCE ON COMPUTING (ICOCO), 2021, : 103 - 108
  • [45] Spanning tree search model to traceback DDoS attack using netflow
    Lee, M
    Jung, S
    Kwon, Y
    Kim, K
    Moon, J
    Byeon, O
    SAM'03: PROCEEDINGS OF THE INTERNATIONAL CONFERENCE ON SECURITY AND MANAGEMENT, VOLS 1 AND 2, 2003, : 330 - 333
  • [46] A Combined Harris Hawks and Dragonfly Optimization Approach for Feature Selection in MLP-Based DDoS Attack Detection
    Ghasem, J.
    Salah-hassa, R.
    Firouzjah, K. Gorgani
    INTERNATIONAL JOURNAL OF ENGINEERING, 2025, 38 (08): : 1898 - 1908
  • [47] Feature Bundles and their Effect on the Performance of Tree-based Evolutionary Classification and Feature Selection Algorithms
    Neshatian, Kourosh
    Varn, Lucianne
    2019 IEEE CONGRESS ON EVOLUTIONARY COMPUTATION (CEC), 2019, : 1612 - 1619
  • [48] Performance evaluation of feature selection and tree-based algorithms for traffic classification
    Aouedi, Ons
    Piamrat, Kandaraj
    Parrein, Benoit
    2021 IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS WORKSHOPS (ICC WORKSHOPS), 2021,
  • [49] Detection of Android Malware using Tree-based Ensemble Stacking Model
    Shafin, Sakib Shahriar
    Ahmed, Md Maroof
    Pranto, Mahmud Alam
    Chowdhury, Abdullahi
    2021 IEEE ASIA-PACIFIC CONFERENCE ON COMPUTER SCIENCE AND DATA ENGINEERING (CSDE), 2021,
  • [50] Optimized Intrusion Detection for IoMT Networks with Tree-Based Machine Learning and Filter-Based Feature Selection
    Balhareth, Ghaida
    Ilyas, Mohammad
    SENSORS, 2024, 24 (17)